Skip to content

TheHackerWitch-Official/Magento-Shoplift-SQLI

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

9 Commits
 
 
 
 
 
 
 
 

Repository files navigation

Magento-Shoplift-SQLI

Proof of Concept code of the Shoplift code

This is code exploits a few pretty big flaw in the very popular webshop CMS Magento.

I did not find the exploit, all credits go to Checkpoint. You can read their technical public disclosure here: Analyzing the Magento Vulnerability

Sucuri has a nice blog post about how this flaw is being exploited in the wild: Magento Shoplift (SUPEE-5344) Exploits in the Wild

Byte.nl made a online scanner to see if a website is vulnerable: https://shoplift.byte.nl/markup

To Execute

python2 poc.py target_address

About

Proof of Concept code of the Shoplift code

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Python 100.0%